Skip to content

Trivy

v0.71.1 Bugfix

This release fixes issues for SREs watching stability and regressions.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

containers security docker go iac kubernetes
+5 more
misconfiguration security-tools vulnerability vulnerability-detection vulnerability-scanners

Summary

AI summary

Fixed artifact filename validation, scanner options forwarding, VEX document loading, and error surfacing.

Changes in this release

Bugfix Medium

Fixes OCI artifact filename validation.

Fixes OCI artifact filename validation.

Source: llm_adapter@2026-06-15

Confidence: high

Bugfix Medium

Forwards ospkg detector options through ospkg.NewScanner.

Forwards ospkg detector options through ospkg.NewScanner.

Source: llm_adapter@2026-06-15

Confidence: high

Bugfix Medium

Loads VEX documents from the repository directory.

Loads VEX documents from the repository directory.

Source: llm_adapter@2026-06-15

Confidence: high

Bugfix Medium

Surfaces original analysis error instead of context cancellation.

Surfaces original analysis error instead of context cancellation.

Source: llm_adapter@2026-06-15

Confidence: high

Full changelog

Changelog

  • 164b383121351c2d49c5d354c2245719d972752b release: v0.71.1 [release/v0.71] (#10818)
  • a72d9a4d997c25fbb6534e231b4e206c9b202b31 fix(oci): validate artifact filename
  • 3dd98471dfbbc4a95edd5cd866468d3a8c87fd17 fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#10825)
  • a62cbe40a240d3a3f568401b8a5f86e14114e371 fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#10821)
  • 43d1d2628725e913db110b89419f0bebd36f58a8 fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#10812)
  • ac7696c7b50d633183ce2ff44898d4b5c6eae565 ci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#10815)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Trivy

Get notified when new releases ship.

Sign up free

About Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

All releases →

Beta — feedback welcome: [email protected]